Public Wi-Fi and two-factor authentication: what every user needs to know
A familiar situation: using the airport Wi-Fi
Imagine this: you’re at the airport, waiting for your flight, and it occurs to you that you still need to make a quick bank transfer or log into your work email account. You see „Airport_FreeWiFi – open network” on the screen. One click, and you’re connected. Convenient, quick and free.
But is it safe as well?
This scenario is repeated millions of times a day all over the world. In cafés, hotels, shopping centres and libraries. Public Wi-Fi is now almost a basic service. However, what is convenient is not always secure, and this is particularly true of open networks.
Why is public Wi-Fi so appealing, and why does it pose risks?
The main advantage of public Wi-Fi is clear: you don’t have to use up your mobile data allowance, the connection is usually fast, and it’s available free of charge. It can be a real help when travelling, outside of work, or whilst waiting for a long time.
The problem is that, in most cases, these networks they are not encrypted, or they are protected by a password known to everyone, which is almost the same as if they were completely open. This means that anyone on the same network with the right technology can intercept the data traffic.
Think of it as having a phone conversation in a crowded café: if you speak loudly, the people sitting at the next table will be able to hear what you’re saying.
How can attackers exploit a public network?
The literature on cyber security and organisations such as the CISA (the US Cybersecurity and Infrastructure Security Agency) or the OWASP Several typical attack methods used in public Wi-Fi environments have been identified. We summarise the most important ones in simple terms.
Man-in-the-middle attack
The most common and most serious threat. An attacker „intercepts” the connection between your device and the internet: all the data you send or receive passes through the attacker’s machine without you realising it. Think of it as a postman who opens your letter, reads it, then seals it back up and passes it on, and you have no idea that this has happened.
Fake networks (Evil Twin)
The attacker sets up a network with a name that is almost identical to that of a genuine, trustworthy network. For example, in a café, you might find „CaféWifi” and „CafeWifi” side by side. If you accidentally connect to the fake one, all your traffic will be routed through the attacker.
Session Hijacking
This is the type of attack that is particularly worth paying attention to, and which is explained in detail in our video on the subject.
When you log in to a website or app, the server assigns a unique, temporary identifier – known as a session token – to your device. This „active connection” maintains your logged-in status. An attacker often doesn’t even need your password: all they need to do is obtain this active session token. They can then log into your account as if they were you, without knowing your password or your 2FA code.
To use an analogy, it’s like a safe that’s been left open: if someone gets hold of it whilst the door is already open, they no longer need the combination, even if there is a lock on it.
A quick login over your lunch break using a café’s guest Wi-Fi could be enough for this to happen, whilst you’re under the impression that you’ve gone about your business safely.
Why does two-factor authentication not provide complete protection on its own?
A two-factor authentication (2FA) one of the most effective and highly recommended security solutions. This is confirmed by all reliable sources, including the NIST (the US National Institute of Standards and Technology) also emphasises this. The essence of 2FA is that, in addition to a password, it requires a second form of authentication: for example, a code sent via text message, a number generated by an authentication app, or a physical security key.
This does indeed provide significant protection, but it does not provide complete safety in every situation.
When is 2FA not enough?
In the event of a work process diversion: If you have already logged in and an attacker obtains your session token, 2FA no longer provides protection. You have already logged in, and the token is valid. This is precisely the scenario that is most difficult to prevent on public Wi-Fi.
In the event of real-time data theft: An attacker can „intercept” communications in real time between your device and the genuine website via a public network. You enter your password and 2FA code, and the attacker immediately forwards them to the genuine site, obtains the session token, and then takes control of your account. The whole process takes just a few seconds.
In the case of a SIM swapping attack: Although this isn’t directly related to Wi-Fi, it’s worth noting that SMS-based two-factor authentication (2FA) can be bypassed by obtaining your phone number. That’s why it’s a good idea to use an authentication app instead of SMS.
In summary: 2FA is an essential layer of security, but it is no substitute for exercising caution when using public networks. The two work effectively together, rather than one in place of the other.
Which accounts are most at risk?
Not all accounts pose the same level of risk, but the following are particularly vulnerable on public Wi-Fi:
- Email accounts: Email is the „key” to almost every other account. Most password recovery processes rely on it. If an email account is compromised, all your other accounts could be at risk.
- Banking and financial applications: Direct financial loss may occur if an attacker gains access to online or mobile banking.
- Social media accounts: Személyes adatok, üzenetek, kapcsolati hálók kerülhetnek illetéktelen kezekbe. Vállalkozások esetén egy feltört céges közösségi profil komoly reputációs kárt okozhat.
- Vállalati fiókok (VPN, belső rendszerek, levelezés): Kisvállalkozásoknál különösen veszélyes, ha egy munkavállaló nyilvános Wi-Fi-ről lép be a vállalati rendszerekbe, ez az egész cég adatait kockáztatja.
Milyen jelek utalhatnak gyanús hálózatra?
Néhány figyelmeztető jel, amire érdemes odafigyelni:
- Hasonló nevű, de ismeretlen hálózat: Ha egy helyen egyszerre több, egymáshoz hasonló nevű hálózat jelenik meg (pl. „HotelWifi” és „Hotel_Wifi”), az egyikük hamis lehet.
- Jelszó nélküli, nyílt hálózat: Különösen gyanús, ha olyasminek nevezi magát, ami jellemzően nem szokott nyílt lenni (pl. egy bank vagy kormányzati intézmény neve).
- Böngésző biztonsági figyelmeztetések: Ha a böngésző „Nem biztonságos kapcsolat” vagy tanúsítványhibára figyelmeztet, ne folytasd a munkát.
- Szokatlanul lassú kapcsolat: Nem mindig jele támadásnak, de közbeékelődéses támadásnál előfordulhat, hogy az adatforgalom lassabb, mivel egy közvetítőn halad át.
- Bejelentkezési oldalt kér a Wi-Fi-hez: Az úgynevezett „captive portal” önmagában nem gyanús, de ha ismeretlen, furcsa kinézetű oldalra irányít, érdemes óvatosnak lenni.
Mit tehetsz a védelem érdekében?
A jó hír: néhány egyszerű lépéssel jelentősen csökkenthetők a kockázatok. A CISA és az NIST ajánlásaival összhangban az alábbiakat javasoljuk:
Használj mobilinternetet érzékeny műveleteknél
Ha banki ügyeket intézel, munkahelyi rendszerbe lépsz be, vagy fontos e-mailt küldesz, kapcsold ki a Wi-Fi-t és használd a mobilhálózatot. A mobilhálózat jóval nehezebben lehallgatható, mint egy nyílt Wi-Fi.
Használj VPN-t
A VPN (Virtual Private Network) egy titkosított „alagutat” hoz létre az eszközöd és a szerver között, így még ha valaki figyeli is a forgalmat, csak titkosított, értelmezhetetlen adatokat lát. Megbízható, fizetős VPN-szolgáltatás használata erősen ajánlott, különösen üzleti felhasználók számára.
Kapcsold ki az automatikus Wi-Fi csatlakozást
Sok okostelefon automatikusan csatlakozik ismert vagy nyílt hálózatokhoz. Ezt érdemes kikapcsolni, hogy tudatosan választhasd meg, mikor és melyik hálózathoz csatlakozol.
Kerüld a fontos bejelentkezéseket nyilvános hálózaton
A „csak egy perc” szemlélet a legveszélyesebb. Ha nem feltétlenül szükséges, ne lépj be banki, vállalati vagy e-mail fiókodba nyilvános Wi-Fi-ről.
Használj kétfaktoros azonosítást okosan
A 2FA-t mindenképpen kapcsold be minden fontos fiókodon, különösen az e-mailnél, a bankoknál és a munkahelyi rendszereknél. Ahol lehetséges, válassz hitelesítő alkalmazást (pl. Google Authenticator, Microsoft Authenticator) az SMS-alapú kód helyett, mivel az alkalmazás alapú megoldás ellenállóbb bizonyos támadásokkal szemben.
Tartsd naprakészen eszközeidet és alkalmazásaidat
A rendszeres frissítések nem csupán új funkciókat hoznak: a biztonsági rések javítása az egyik legfontosabb feladatuk. Egy frissítetlen eszköz ismert sérülékenységeket hordoz, amelyeket a támadók könnyen kihasználhatnak – akár nyilvános hálózaton, akár anélkül.
Összegzés: a tudatosság a legjobb védekezés
A nyilvános Wi-Fi nem ördögtől való és nem kell rémálomként tekinteni rá. Ugyanakkor fontos megérteni, hogy egy nyílt hálózat mindig magasabb kockázatot jelent, mint a saját, jelszóval védett otthoni vagy irodai kapcsolat.
A kétfaktoros azonosítás valóban az egyik leghatékonyabb védelmi eszköz, amelyet ma használhatsz, de nem csodaszer. Nyilvános hálózaton olyan extra kockázatok léphetnek fel, különösen a munkamenet-eltérítés formájában, amelyekkel szemben a 2FA önmagában nem nyújt teljes védelmet.
A jó hír: néhány egyszerű szokás kialakításával, pl. VPN, mobilinternet használata érzékeny műveleteknél, automatikus csatlakozás kikapcsolása, rendszeres frissítések és átgondolt 2FA-használatával, a legtöbb kockázat kezelhető szintre csökkenthető.
A kiberbiztonság nem egyetlen lakat a kapun, hanem egymást erősítő rétegek összessége. Minél több réteget alkalmazol, annál nehezebb dolga lesz annak, aki meg akarja kerülni azokat.
Nincs időd végigolvasni minden részletet? A témát egy rövid, átfogó videóban is feldolgoztuk, ahol a legfontosabb gondolatokat emeltük ki. Itt tudod megnézni: